web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / Power Automate HTTP Tr...
Power Automate
Suggested Answer

Power Automate HTTP Trigger Authentication with Entra ID App Registration

(0) ShareShare
ReportReport
Posted on by

I am building an integration where an external application needs to trigger a Power Automate cloud flow via the "When an HTTP request is received" trigger.

 

The flow works correctly when invoked manually, and I have the generated HTTP endpoint URL.

 

The external application team is configuring a Microsoft Entra ID App Registration and has asked for the following information:

 

  • Redirect URL (Redirect URI)

  • Audience / Resource URI

  • Application ID URI

  • Tenant-related authentication details


  •  
 

I am trying to understand how Power Automate HTTP-triggered flows are intended to be secured using Microsoft Entra ID authentication.

 

My questions are:

 

  1. What is the recommended authentication model for an external application calling a Power Automate HTTP-triggered flow?

  2. Should OAuth 2.0 Authorization Code Flow or Client Credentials Flow be used?

  3. If Authorization Code Flow is used, where can the Redirect URI be obtained?

  4. Does the Power Automate HTTP trigger expose an Audience/Resource URI that should be used during Entra ID app registration?

  5. Is there Microsoft documentation showing the complete Entra ID configuration required for an external application to securely invoke a Power Automate HTTP endpoint?


  6.  
 

I am specifically looking for guidance on the Entra ID configuration and OAuth setup required to authenticate calls to a Power Automate HTTP trigger.

 

Thanks in advance.

Farhad

 

ps: the attachment is null

Categories:
I have the same question (0)
  • Suggested answer
    11manish Profile Picture
    3,961 Super User 2026 Season 2 on at
    For your external application, don't create a Redirect URI unless you actually need an interactive user login. For a background/server integration, start with OAuth 2.0 Client Credentials.
    Most importantly, don't invent the Audience/Application ID URI. The resource/API that validates the access token must define the expected audience. If the Power Automate HTTP trigger configuration in your environment doesn't expose a supported way to configure/validate an Entra audience, introduce API Management/Azure Function as the secured API façade and let that layer authenticate the external application before invoking the flow.
     
    Refer:
     
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Automate

#1
David_MA Profile Picture

David_MA 298 Super User 2026 Season 2

#2
trice602 Profile Picture

trice602 159 Super User 2026 Season 2

#3
11manish Profile Picture

11manish 150 Super User 2026 Season 2

Last 30 days Overall leaderboard